URLhaus Database

You are currently viewing the URLhaus database entry for http://178.16.53.7/cvdfnaFJBmC1/Plugins/cred.dll which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3614684
URL: http://178.16.53.7/cvdfnaFJBmC1/Plugins/cred.dll
URL Status:flame Online (spreading malware for 2 months, 20 days, 17 hours, 55 minutes)
Host: 178.16.53.7
Date added:2025-08-31 11:45:08 UTC
Threat:Malware download Malware download
Reporter: BlinkzSec
Abuse complaint sent (?): Yes (2025-08-31 11:46:12 UTC to abuse{at}metaspinner[dot]net,info{at}metaspinner[dot]net)
Tags:Amadey ua-wget

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-10-27cred.dlldll 68fd9dcdd529624f49562e2b5c4f6d979ee4ef5be10d6994314404c7a4acc7cen/a Amadey
2025-10-14cred.dlldll 5d4f9fdaab1126aab46652695cf687bb08f3de7ac72bf278df323d7c1b07ff0bVirustotal results 48.48% Amadey
2025-08-31cred.dlldll 32e5627bca1cffa8987efc931033cdf85f641896bfac522ff97def41f42cd050Virustotal results 62.50% Amadey